CVE-2004-1060

Scores

EPSS

0.599medium59.9%
0%20%40%60%80%100%

Percentile: 59.9%

CVSS

5.0medium2.0
0246810

CVSS Score: 5.0/10

All CVSS Scores

CVSS 2.0
5.0

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Description

Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP (“Fragmentation Needed and Don’t Fragment was Set”) packets with a low next-hop MTU value, aka the “Path MTU discovery attack.” NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

Exploits

Exploit ID: 25388

Source: exploitdb

URL: https://www.exploit-db.com/exploits/25388

Exploit ID: 942

Source: exploitdb

URL: https://www.exploit-db.com/exploits/942

Vulnerable Software (2)

Type: Configuration

Vendor: *

Product: icmp

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:icmp:icmp:*:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:tcp:tcp:*:*:*:*:*:*:*:*",      "vulnerable": true...

Source: nvd

Type: Configuration

Vendor: *

Product: tcp

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:icmp:icmp:*:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:tcp:tcp:*:*:*:*:*:*:*:*",      "vulnerable": true...

Source: nvd

End of list